Cybersecurity requirements exist for good reason. The systems we rely on hold highly sensitive information, connect increasingly complex environments, and face threats that continue to evolve in both sophistication and scale. As those environments have become more complex, however, the burden placed on individual users has grown with them.
Consider what we routinely ask people to do: manage strong, unique credentials; recognize phishing attempts; evaluate links before clicking them; respond appropriately to multifactor authentication prompts; protect sensitive information; keep devices and software updated; and navigate multiple systems, policies, and access requirements. Progressively, they must also determine when and how emerging technologies such as artificial intelligence can be used safely.
None of these expectations is unreasonable on its own. The challenge is their cumulative effect on a person who is also trying to do their actual job.
When security processes become too difficult, slow, confusing or disconnected from the way people work, people adapt. They reuse passwords, dismiss warnings they have seen too many times, find faster ways to move information between systems or adopt tools that help them accomplish a task before those tools have been formally approved.
The traditional response is often to focus on the user: Why did they do that? Did they understand the policy? Do they need more training? Those may be appropriate questions, but when the same behaviors emerge repeatedly, we should also ask: What is the behavior telling us about the system we created?
That question matters. Verizon reported that 60 percent of breaches analyzed in its 2025 Data Breach Investigations Report involved some form of human element. NIST has also begun developing guidance specifically around human-centered cybersecurity, placing people’s needs, abilities, and limitations at the forefront of how cybersecurity is designed and implemented.
Security that does not account for predictable human behavior can inadvertently create new risk. Secure by Design gives us an opportunity to think about cybersecurity not simply as a collection of controls users must comply with, but as an experience we intentionally design.
Humans Respond to Complexity Like Humans
Cybersecurity has often described people as the “weakest link.” That framing can obscure something important: human behavior is not random.
Passwords offer a familiar example. For years, users were asked to create increasingly complex passwords, change them periodically, and maintain different credentials across a growing number of systems. People responded predictably. They reused passwords, created recognizable variations, wrote them down, or found other ways to reduce the cognitive burden.
NIST’s current Digital Identity Guidelines reflect what the industry learned from that experience. SP 800-63B-4 directs organizations not to impose password composition rules requiring particular combinations of character types and not to require periodic password changes absent evidence of compromise. NIST’s rationale acknowledges that people have limited ability to memorize complex, arbitrary secrets and that traditional composition rules can impose significant usability costs without delivering the security benefit once assumed.
The security objective did not disappear. The approach evolved to reflect how people actually behave.
Attackers already understand this principle. Social engineering is effective precisely because it is designed around predictable human responses such as trust, urgency, authority, fatigue and distraction. MFA fatigue attacks rely on repetition and annoyance. Business email compromise pairs impersonation with urgency. Phishing increasingly follows people into text messages, collaboration platforms and other environments they already trust.
Even security warnings can create predictable behavior. When people encounter enough generic prompts and banners, clicking through them can become habitual. An attacker does not necessarily need to defeat a technical control if a user has already been conditioned to dismiss it.
Attackers devote considerable effort to understanding how people behave and designing their attacks accordingly. Defenders should apply at least as much attention to human behavior when designing the systems and controls intended to protect them.
Make the Secure Path the Path of Least Resistance
Fortunately, security and usability do not have to be competing objectives. Password managers reduce the need to memorize dozens of unique credentials. Phishing-resistant MFA and passkeys can remove the decision point exploited by MFA fatigue attacks. Single sign-on reduces the number of credentials users manage, while better-designed security prompts can explain why an action presents risk and what the safer alternative is instead of relying on generic warnings.
The same principle applies to emerging challenges. When employees consistently turn to unapproved AI tools, for example, organizations certainly need to address the security and governance implications. But widespread “shadow AI” can also be a design signal: What need are people trying to meet that the sanctioned environment is not meeting? Understanding that need does not excuse unsafe behavior; it helps organizations design a safer alternative people will actually use.
This thinking is increasingly reflected in federal cybersecurity guidance. CISA’s Secure by Design principles seek to move more of the burden of security away from customers and toward the organizations designing technology. NIST’s emerging work on human-centered cybersecurity similarly cautions against relying on awareness training alone when underlying problems include disruptive processes or difficult-to-use security tools.
That philosophy should extend to the experience of security itself.
Meeting a technical or compliance requirement is essential, but it should not be the final question. Alongside “Does this satisfy the control?” teams should ask:
- How will a real person experience this?
- What behavior does the design encourage?
- Where does it introduce friction?
- What workaround might someone facing a deadline develop?
- Could we achieve the same security objective while making the secure behavior easier?
Answering those questions means bringing cybersecurity, compliance, engineering, human-centered design, mission teams and users together early enough to influence how security is implemented. It also means paying attention to friction. Repeated errors, abandoned workflows, unofficial processes and shadow tools should not automatically be treated as evidence that employees need more training. Sometimes they are evidence that the system needs better design.
People do not exist outside the security system; they are part of it. Designing around real human behavior does not mean removing necessary friction or weakening controls. It means being deliberate about where friction exists, why it exists, and what behavior it is likely to produce.
When the secure choice is also the clearest, easiest, and most natural choice, good design is doing some of the security work for us.
That may be one of the most human-centered ideas behind Secure by Design: doing the right thing should not have to be the hard thing.